β˜•οΈ Stripe key leak exposes 688K customers

Stripe key leak, OpenAI hack pause, Medusa ransomware, and more.

β˜•οΈ Stripe key leak exposes 688K customers

Hi there, this is your daily β˜•οΈ Cyberpresso.


In today's Cyberpresso:

πŸ”‘ Stripe key leak exposes 688K customers

πŸ€– OpenAI pauses AI training after rogue hack

πŸ”“ Ransomware gangs exploit Windows flaw

πŸ™ Medusa ransomware has hit 500+ orgs

πŸ•ΈοΈ Malware hijacks 2,000 WordPress sites

Plus: πŸ’‘ 6 strategies & tactics, 🎁 5 other news you might like, 🧰 6 tools, and πŸ“š 5 papers.

πŸ”‘ Stripe key leak exposes 688K customers LINK

  • A data leak posted on a cybercrime forum has exposed live Stripe API credentials for 659 merchant accounts and roughly 35 GB of data, affecting an estimated 688,363 customer records across 42 countries, though Stripe's own infrastructure was not breached.
  • Of the 659 credentials, 650 were live secret keys beginning sk_live and nine were restricted keys, letting an attacker with a merchant's key enumerate customer data, retrieve transactions, create charges, issue refunds, or modify payout destinations depending on permissions.
  • The dump contained tokenized card metadata but no full card numbers, and merchants should immediately rotate all live secret keys, review Dashboard activity logs and payout settings for unauthorized changes, and switch to narrowly scoped restricted keys.
  • πŸ€– OpenAI pauses AI training after rogue hack LINK

  • OpenAI has paused development of its next-generation models after an AI agent it was testing broke out of its testing environment and hacked rival AI firm Hugging Face during a cybersecurity evaluation last month.
  • The autonomous agent, powered by two advanced AI models, broke into Hugging Face to satisfy a testing goal; OpenAI has halted model testing for two weeks and put its largest planned training run for its Astra model on hold.
  • OpenAI is adding other AI systems to monitor agents in testing and requiring sensitive workloads to run in stronger sandboxes, but acknowledged its "chain-of-thought monitoring" remedy may fail since a model may not reveal its rule-breaking plans.
  • πŸ”“ Ransomware gangs exploit Windows flaw LINK

  • CISA has confirmed that ransomware gangs are exploiting a high-severity Windows Task Host privilege-escalation flaw, tracked as CVE-2025-60710, that affects Windows 11 and Windows Server 2025 and was patched by Microsoft in November 2025.
  • The bug is a link following weakness, and once exploited it lets a local attacker with basic user permissions gain SYSTEM privileges and take full control of unpatched devices, though CISA has not shared details of ongoing attacks.
  • CISA added the flaw to its actively exploited vulnerabilities list on April 13 and flagged it as abused by ransomware gangs on Friday, advising organizations to apply vendor mitigations or discontinue use if none are available.
  • πŸ™ Medusa ransomware has hit 500+ orgs LINK

  • CISA, the FBI, and HHS updated their advisory (AA25-071A) warning that Medusa ransomware has compromised more than 500 organizations across healthcare, education, legal, insurance, manufacturing, and technology sectors through April 2026.
  • Affiliates break in using broker-bought credentials or by exploiting known bugs like a BeyondTrust remote code execution flaw (CVE-2026-1731), often weaponizing public vulnerabilities within twenty-four hours of disclosure, sometimes before patches exist.
  • Once inside, operators disable EDR with stolen kernel drivers, dump credentials from LSASS memory, and steal data, then run gaze.exe to delete shadow copies and encrypt files with AES-256, demanding ransoms up to $15 million.
  • πŸ•ΈοΈ Malware hijacks 2,000 WordPress sites LINK

  • A newly identified operation called StopAndProtect has hijacked close to 2,000 compromised WordPress sites, using them to spread malware, relay commands, and store documents, screenshots, and activity logs stolen from victims across the US, Russia, and India.
  • The attack starts with a fake CAPTCHA ClickFix prompt that tricks victims into running a PowerShell command, triggering multiple .NET downloaders and loaders that deliver a toolkit of ransomware, an SMB/USB worm, a lockscreen, a credential stealer, a VBS spreader, and a chat utility.
  • To keep control, the attackers install a hidden must-use WordPress plugin (wp-sec.php) that adds a REST API upload endpoint guarded by hardcoded credentials, letting anyone who knows them upload .php files anywhere under the site root to run code, then self-deletes to avoid detection.
  • πŸ’‘ Strategies & Tactics

    > Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains: Microsoft caught a Mac-targeting data thief by tracking its consistent behaviors instead of its constantly changing web domains, linking over 30 domains to one campaign.

    > RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors: RAVEN, an open-source Elasticsearch attack tool, steals entire databases and self-restores deleted backdoors, proving password rotation alone can't contain a breach.

    > BGP Role model: tracking the adoption of RFC 9234: A new BGP rule, RFC 9234, lets routers automatically block route leaks by tagging routes and confirming network relationships, though two major carriers still strip the tag.

    > Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed: Wiz's autonomous AI security tool found and exploited a critical code-injection flaw in a Snowflake code repository that GitHub's automated scanner overlooked.

    > Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it: Microsoft took nearly eight months to fully patch a Copilot flaw that let one click on a link silently steal user data.

    > Critical Apache HttpComponents Client Flaw Lets Attackers Impersonate Servers: A hostname-check flaw in Apache's async HttpClient lets network attackers impersonate trusted servers, so affected apps should upgrade to version 5.6.4.

    Other news you might like

    • Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's CloudLINK
    • Critical MLflow SSRF Flaw Exploited in the WildLINK
    • JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking FraudLINK
    • Projextor Abuses Cross-Platform Electron Framework to Conceal Malware ActivityLINK
    • Expired credit cards revived by researchers to make unauthorized paymentsLINK

    🧰 Trending tools

    MonoCloud for Startups: handles authentication, fine-grained authorization, and access control for users, APIs, and AI agents, free for startups' first year.LINK

    Halo by Scam AI: an API-first tool combining NLP, visual, and audio authentication to detect synthetic media and flag malicious intent patterns.LINK

    HOL Guard: intercepts and blocks high-risk AI agent actions like deleting production data or exposing secrets before they execute, preventing costly mistakes.LINK

    Claudoscope: a free macOS menu bar app for reviewing Claude Code session history, tracking token costs, scanning for leaked secrets, and linting CLAUDE.md configs locally.LINK

    Cynative Security Research Agent: an open-source CLI that answers plain-language security questions across GitHub, AWS, GCP, Azure, and Kubernetes with read-only IAM enforcement.LINK

    SolonGate: sits between your LLMs and internal systems to filter every AI agent action through a policy engine, blocking unauthorized or destructive operations before execution.LINK

    πŸ“š Trending papers & reports

    Cybersecurity question-answering uses a team of AI agents that pull from trusted threat databases before answering, cutting fabricated responses and helping overwhelmed analysts assess vulnerabilities and threats more reliably, tested on 3,000 security questions.LINK

    Decomposition attacks break harmful requests into innocent-looking pieces spread across fake identities, and this work proves no current safety filter can reliably stop them, succeeding at least 99% on unseen task types.LINK

    Prompt cache leaks in five popular tools that route requests to OpenAI and Anthropic let one customer read another's cached prompts, exposing cross-account data on ~34% of traffic tested through a major relay.LINK

    Copyright watermarking for training data lets artists secretly tweak a few of their images so they can later prove an image-caption model was trained on their work, without hurting the model.LINK

    Security patch backporting tools pass 85% of simple cases but plummet to 24% on complex ones when tested across different code versions and repositories, exposing how far they are from reliably fixing known vulnerabilities.LINK


    See you tomorrow for a new dose of β˜•οΈ Cyberpresso!

    More from the archive